Application Security Analyst
United States$75k–$110kPosted Jul 16, 2026
About Sound
Founded in 2001 and headquartered in Nashville, TN, Sound Physicians is a nationally respected, physician-led medical group practicing in 400+ hospitals across 45 states. Our team of 4,000+ clinicians and 1,000+ business professionals across the country is united by one mission: to build exceptional clinical partnerships that unlock quality, affordable, dignified care for everyone – no matter who they are or where they live. With physician-led clinical teams and more than two decades of operational expertise, we’ve refined what it takes to consistently deliver exceptional care in hospital medicine, emergency medicine, critical care, anesthesia, and telemedicine.
Why join us?
A remote-first culture that values flexibility and collaboration
Opportunities to grow your career while making a real impact
A team that champions inclusivity, innovation, and excellence
Whether working virtually or onsite at one of our practices, you’ll be part of a purpose-driven organization shaping the future of healthcare.
Sound Physicians offers a competitive benefits package inclusive of the items below, and more:
Medical insurance, Dental insurance, and Vision insurance
Health care and dependent care flexible spending account
401(k) retirement savings plan with a company match
Paid time off (PTO) begins accruing immediately upon start date at a rate of 15 days per year, in accordance with Sound's PTO policy
Ten company-paid holidays per year
About the Role
The Application Security Analyst helps embed security into the software delivery lifecycle by partnering with development, platform, cloud, and security teams to build secure-by-default processes. This role focuses on reducing risk through automation, continuous testing, secure configuration, and practical guidance that enables teams to ship software quickly and safely. The ideal candidate possesses a strong understanding of application security principles, secure coding practices, cloud security controls, vulnerability management, and modern DevSecOps methodologies.
The Details:
Participation in the after-hours security incident response and on-call rotation is part of the role.
Essential Duties and Responsibilities
Integrate security controls and automated checks into CI/CD pipelines, including Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), secret scanning, container security scanning, and Infrastructure-as-Code (IaC) validation.
Partner with developers and platform engineers to identify, prioritize, and remediate application, API, container, and cloud security risks early in the development lifecycle.
Perform application security assessments, architecture reviews, and threat modeling exercises for new and existing applications.
Support vulnerability management by validating findings, reducing false positives, tracking remediation, and helping define risk-based service-level expectations.
Conduct secure code reviews and provide guidance on secure coding practices aligned with OWASP Top 10, CWE, and industry standards.
Perform security reviews for application architecture, deployment patterns, third-party components, and cloud configurations.
Develop and maintain secure pipeline standards, reusable guardrails, and policy-as-code checks that improve consistency without creating unnecessary delivery friction.
Collaborate with engineering, infrastructure, and security operations teams on incident response, root cause analysis, and hardening activities related to software delivery platforms.
Create and maintain documentation, standards, playbooks, and training materials related to application security, secure development, and DevSecOps practices.
Track vulnerability trends, security metrics, and recurring issues to improve security maturity across build, release, and runtime workflows.
Stay current on emerging threats, attack techniques, vulnerabilities, and security technologies...